Director for Malicious Infrastructure Discovery @ Recorded Future | Views my own

Joined November 2022
Photos and videos
Calwarez retweeted
In August 2025, @_whoisnt and I documented how Stark Industries evaded EU sanctions. This week, Dutch authorities arrested two individuals and seized hundreds of servers linked to WorkTitans BV in an investigation into sanctions evasion. volkskrant.nl/binnenland/how…
1
6
9
2,406
Calwarez retweeted
New from @RecordedFuture! @_whoisnt and I break down Threat Activity Enablers (TAEs), the often overlooked backbone of modern cyber operations. 🔗recordedfuture.com/blog/thre…
7
35
2,863
Calwarez retweeted
OMEGATECH (AS202412) is the latest installment of Threat Activity Enabler Virtualine Technologies, following their transition away from Railnet LLC.
NEW: Block one ASN, disrupt sixteen malware families. OMEGATECH (AS202412) — a three-month-old bulletproof hosting network with 18 /24 prefixes (4,608 IPs). One subnet alone hosts 67 C2 servers: Remcos (6,562 sightings), AsyncRAT (4,379), Amadey, Latrodectus, XWorm, Stealc, DCRat, LOBSHOT, Eye Pyramid, Mirai, Bashlite, Quasar, ClearFake, SectopRAT, SuperShell, SheetRAT. Seychelles .sc abuse contact. Pfcloud UG transit. Zero legitimate traffic. We recovered an Amadey credential stealer plugin (cred64.dll) targeting Chrome, Firefox, Outlook, Thunderbird, FileZilla, WinSCP, and Monero wallets. 3 YARA 10 Suricata on GitHub. Full writeup: intel.breakglass.tech/post/o… h/t @Fact_Finder03
2
3
353
🧵 ICYMI: We just dropped our 2025 Malicious Infrastructure Review! Some of the highlights below👇 #Infosec #CyberThreats 1/6
1
2
5
206
Threat actors are increasingly abusing Legitimate Internet Services (LIS) like Cloudflare, Google Drive, and Telegram to hide in plain sight. It’s a structural challenge for every network defender. 5/6
1
1
56
Calwarez retweeted
Noticed Microsoft Defender tagging #TheVoidStealer as #WallStealer thanks to some recent @abuse_ch uploads. Here’s the threat actor nikoniko (aka “TheVoidStl”) discussing the removal of multiple detections, including WallStealer.
23 Dec 2025
Void Stealer Tor C2 panel http[://ddccvyclo5p7qdwkvgithmfd2wensrnuvz6hfpjqupgsyzalvq6h4xid.onion/fakjak3ak/aghgfaasfaa/login I have a mid confidence that below IOCs belongs to Void Stealer. intercttp[.xyz jjjgaasda[.live 151[.243.113.71:8080 83[.217.209.227:8080 185[.107.74.138:8080 193[.233.112.254:8080 @500mk500 !!
2
4
17
5,026
Calwarez retweeted
CVE-2026-25253  ⚠️ OpenClaw (Moltbot / Clawdbot) – 1-Click RCE via Token Exfiltration  A high-severity vulnerability (CVSS 8.8) has been disclosed in OpenClaw allowing remote code execution with a single click.  The flaw is a logic issue where the Control UI blindly trusts a gatewayUrl supplied via query string and auto-connects over WebSocket, leaking the stored gateway token to attacker-controlled infrastructure.  By abusing cross-site WebSocket hijacking and privileged operator scopes, attackers can disable safety approvals, escape the container, and execute arbitrary commands directly on the host even when the gateway is bound to localhost only.   Modat previously identified exposed Clawdbot/Moltbot control panels, with numbers now even higher. You can read the full blog here modat.io/post/moltbot-unmask…   Fixed in: v2026.1.29 
Action: Patch immediately and rotate gateway tokens.  Modat Magnify Query: 
web.title~"Clawdbot Control" OR web.title~"OpenClaw Control" OR web.title~"Moltbot Control"  The platform: 
magnify.modat.io/  #threatintel #vulnerability #CVE202625253 #OpenClaw #Moltbot #Clawdbot #RCE #AIsecurity #infosec #ModatMagnify
2
3
9
1,306
Calwarez retweeted
New Modat Magnify updates are live.  • Time-based filtering  • Unified IP detail view   • Certificate validity filtering (expired, not yet valid, abnormal lifetimes)  • CN wildcard & partial matching  • Issuer Alternative Name (IAN) search  • Empty field search with field=""  • TLS version filtering  • Banner hex search  • New Tags: VPN and PQC over SSH    Built for faster, more precise infrastructure investigations. 
  Explore the new features inside the platform:  magnify.modat.io/
2
2
1,141
Calwarez retweeted
Use YARA for threat hunting? .@theidr0p created a tool for automated YARA rule creation based on the Cert Graveyard. Automatically checks for updates to the database and generates rules. The art is theirs. Amazing. See link in thread for details
1
8
43
2,614
Calwarez retweeted
From 2020-2024, I tracked the SolarMarker malware, and in 2024, monitored a self-infection for months to learn their actions-on-objectives: on-device fraud. I didn't publish the details of my months long investigation until now. Check the link the the attached comment.
2
15
64
8,394
Calwarez retweeted
A Ukrainian national has been federally charged with participating in dozens of cyberattacks and computer intrusions against critical infrastructure and other victims around the world, in support of Russia’s geopolitical interests, the Justice Department announced today. The two indictments against Victoria Eduardovna Dubranova, 33, a.k.a. “Vika,” a.k.a. “Tory,” a.k.a. “SovaSonya,” were unsealed today in United States District Court in Los Angeles. Dubranova was extradited to the United States earlier this year on an indictment charging her for her actions supporting CyberArmyofRussia_Reborn (CARR). Dubranova was arraigned today on a second indictment charging her for her actions supporting NoName057(16) (NoName). Dubranova has pleaded not guilty in both cases. Dubranova pleaded not guilty today at her arraignment and a February 3, 2026 trial date was scheduled in that case. As described in the indictments, the Russian government backed CARR and NoName by providing, among other things, financial support. CARR used this financial support to access various cybercriminal services, including subscriptions to distributed denial of service-for-hire services. NoName was a state-sanctioned project administered in part by an information technology organization established by order of the President of Russia in October 2018 that developed, along with other co-conspirators, NoName’s proprietary distributed denial of service (DDoS) program. Details: justice.gov/usao-cdca/pr/jus…
23
115
233
10,629
Calwarez retweeted
New coordinated reporting from @googlecloud, @AmnestyTech, @RecordedFuture, and @haaretzcom / @insidestory_gr, built on leaked Intellexa material and technical findings, outlines Intellexa’s exploits, corporate structure, and continued activity despite U.S. sanctions. 👇 1/
1
4
21
1,982
Calwarez retweeted
1 Dec 2025
Cyber Monday Deal 
Get 6 months of Modat Magnify Pro for just €5 total (save €355).  Use code: MODAT2025CYBERMONDAY   
Try the platform. Run advanced queries. Find what others miss. 
 magnify.modat.io#CyberMonday #Cybersecurity #OSINT
3
4
973
30 Nov 2025
RT @BushidoToken: 🆕 ICYMI: The @CuratedIntel LinkedIn account is now doing weekly roundup posts based on the member’s latest content: Week…
4
Calwarez retweeted
1/ United States, Australia, and United Kingdom sanction Russian threat activity enabler Media Land (Yalishanda) and follow up on recent designations targeting Aeza. ofac.treasury.gov/recent-act…

1
8
13
977